GHSA-pf8j-vhg8-xmc3CriticalCVSS 9.8

karma-mojo enables OS Command Injection

Published
February 10, 2022
Last Modified
July 6, 2026

🔗 CVE IDs covered (1)

📋 Description

karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.

🎯 Affected products1

  • npm/karma-mojo:<= 1.0.1

🔗 References (4)